Medical technology giant Epic has paused most of its product development. The company is working to protect its software and systems from cyberattacks. MyChart software for accessing patients medical data is created by this company.
Judy Faulkner is the founder and chief executive of Epic. She told Modern Healthcare last month that the pause would likely last six weeks. Work continues on safeguarding company products during this period.
AI cybersecurity model unearthed flaws
An artificial intelligence tool triggered the security fix. Epic deployed Anthropic frontier cybersecurity model Mythos. The deployment unearthed security flaws that could allow access to patients data.
Epic has not disclosed the nature of the bugs. Stirling Martin serves as the chief security officer for the company. He told The New York Times that some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in the software logs.
Martin did not return requests for comment from TechCrunch. He told the Times that the artificial intelligence model did not say if the bug could be exploited to alter patient records without detection. He argued it was enough of a risk to remediate the issues.

MyChart maintains millions of records
MyChart is widely used across the United States. The software maintains over 320 million patient records across hospitals and doctor offices. Epic states it does not have access to customers medical data. Responsibility falls on healthcare providers like hospitals and doctor offices.
A bug unknown to Epic could allow hackers to compromise multiple MyChart affected systems located across the United States. Attackers could raid the data stored within. Healthcare breaches are increasingly common as hackers seek access to sensitive health data.
Read nextCalifornia Attorney General Subpoenas OpenAI Over AI Agent EscapesHackers assume providers will pay to prevent the publication of information online. A 2024 ransomware attack on Change Healthcare allowed hackers to steal health data on more than 192 million people. Change Healthcare is owned by insurance giant UnitedHealth and handles payments for most Americans. That company paid hackers twice not to publish the stolen data.
Back-to-back data breaches have affected tens of millions of Americans this year. Medical records were stolen during a breach at CareCloud. Millions of rows of patient data were taken from McKesson. An unspecified amount of data was stolen from Craneware.
The pause will last six weeks
The Department of Health and Human Services lists a breach at DentaQuest as the largest healthcare related data breach of 2026 so far. That incident affected 15 million people. Epic continues its six week pause on product development to address the identified security vulnerabilities.



